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Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the 

application: 
Listing of Claims: 

1. (Currently Amended) A method to protect a file system from a viral infection, 
comprising: 

allowing one of a highest oocurity lovol, a middle oocurity lovol and a low o ot o o curity 

lovol to be set; 

flagging a program as being suspect for possibly containing a virus without 
performing any virus scanning and detection actions in response to at least one of: 

opening a local file on a local file system to perform a read operation and 
opening a shared file on a shared or network file system to perform a write or append operation with 
the local fil e and th e high o ot o o curity level b e ing s et ; 

the program reading or opening itself and the program attempting to write or 
append any content to the shared file on the shared or network file system or to write or append any 
content to the local file on the local file system and at loaot the medium oocurity l o vol b e ing s e t ; 

the program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system and 
at loaot the lowoot s e curity lovol boing set ; and 

the program attempting to write or append a remote file to the local file 
system and at loaot a medium oocurity l e vel being set; 
storing a filename and a location where the local or shared file i s copied or written in 
response to the local or shared file being copied or written by the program without performing any 
virus scanning and detection actions . 

2. (Currently Amended) The method of claim 1, further comprising inhibiting a write or 
append operation associated with the program in response to flagging the program. 



TRIl\643844vl 



2 



S/N 10/710,477 



Docket No. RSW920040084US1-10 



3. (Original) The method of claim 1, further comprising monitoring all file operations 
associated with the program in response to the program not being in a safe list. 

4. (Original) The method of claim 1, further comprising permitting selected read and write 
operations in response to a predefined rules table. 

5. (Original) The method of claim 1, further comprising sending an alert in response to 
flagging the program. 

6. (Canceled) 

7. (Original) The method of claim 1, further comprising sending an alert to a network 
monitoring system in response to flagging the program. 

8. (Original) The method of claim 1, further comprising logging any file system operations 
including recording a filename and a location where the local or shared file is written. 

9. (Currently Amended) A method to protect a file system from a viral infection, 
comprising: 

allowing a security level to be set; 

monitoring predetermined file system operations associated with a program; and 
logging any predetermined file system operations associated with the program 

including recording a filename and a location where a file is written without perf orming any virus 

scanning and detection actions . 

10. (Original) The method of claim 9, further comprising selecting the program for 
monitoring in response to the program not being on a safe list. 

11. (Original) The method of claim 10, further comprising logging any file system 
operations associated with any programs on the safe list. 
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12. (Original) The method of claim 9, further comprising receiving a notification that the 
program intends to perform one of the predetermined file system operations. 

13. (Previously Amended) The method of claim 9, further comprising following a 
predefined procedure in response to the level of security set. 

14. (Original) The method of claim 9, further comprising flagging the program in response 
to the program attempting to perform one of the predetermined file system operations. 

15. (Original) The method of claim 14, further comprising flagging the program in 

response to at least one of: 

the program opening a local file on a local file system to perform a read operation 
and opening a shared file on a shared or network file system to perform a write or append operation 
with the local file; 

the program reading or opening itself and the program attempting to write or append 
any content to the shared file on the shared or network file system or to write or append any content 
to the local file on the local file system; 

the program attempting to write or append the local file to the shared or network file 
system and preserve a filename of the local file in the shared or network file system; and 

the program attempting to write or append a remote file to the local file system. 

16. (Original) The method of claim 14 , further comprising inhibiting any predetermined 
file system operations associated with the program in response to the program being flagged. 

17. (Original) The method of claim 9, further comprising sending an alert in response to the 
program attempting to perform any predetermined file system operations. 

18. (Original) The method of claim 17, further comprising sending the alert to a network 
monitoring system. 
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19. (Original) The method of claim 9, further comprising presenting an alert to a user for 
approval before the predetermined file system operation is performed by the program. 

20. (Original) The method of claim 9, further comprising requiring approval before 
performing any predetermined file system operations associated the program in response to the 
program not being on a safe list. 

21 . (Currently Amended) A system to protect a file system from a viral infection, 
comprising: 

a file system protection program including: 

means to monitor predetermined file system operations associated with 
another program; 

a plurality of settable levels of security; 

a predefined procedure associated with each level of security to be followed 
in response to a current level of security being set for the predefined procedure and in 
response to an intent to perform a particular file system operation also associated 
with the currently set level of security; and 

means to log any predetermined file system operations associated with the 
other program including recording a filename and a location where a file is written 
without performing any virus scanning and detection actions . 

22. (Original) The system of claim 21, further comprising a safe list, wherein the file 
system program is adapted to monitor the other program in response to the other program not being 
on the safe list. 

23. (Original) The system of claim 21, further comprising a log to record any 
predetermined file system operations. 

24. (Original) The system of claim 21, further comprising means to flag the other program 
in response to at least one of: 
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the other program opening a local file on a local file system to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 

the other program reading or opening itself and the other program attempting to write 
or append itself or any content to the shared file on the shared or network file system or to write or 
append itself or any content to the local file on the local file system; 

the other program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the other program attempting to write or append a remote file to the local file system. 

25. (Original) The system of claim 21, further comprising means to flag the other program 
in response to the other program attempting to perform one of the predetermined file system 
operations. 

26. (Original) The system of claim 25, further comprising means to send an alert in 
response to flagging the other program. 

27. (Original) The system of claim 25, further comprising: 

a network monitoring system; and 

means to send an alert to the network monitoring system in response to flagging the 
other program. 

28. (Original) The system of claim 25, further comprising means to inhibit predetermined 
file system operations associated with the other program in response to the program other being 
flagged. 

29. (Original) The system of claim 25, further comprising: 

means to present an alert to a user; and 
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means for the user to approve the one of the predetermined file system operations 
before being performed by the other program. 

30. (Currently Amended) A method of making system to protect a file system from a viral 
infection, comprising: 

providing a file system protection program including: 

providing means to monitor predetermined file system operations associated 

with another program, 

defining a plurality of settable levels of security; 

providing a predefined procedure associated with each level of security to be 
followed in response to a current level of security being set for the predefined 
procedure and in response to an intent to perform a particular file system operation 
also associated with the currently set level of security; and 

providing means to log any predetermined file system operations associated 
with the other program including recording a filename and a location where a file is written without 
performing any virus scanning and detection actions . 

31. (Original) The method of claim 30, further comprising: 

providing a safe list; and 

adapting the file system protection program to monitor the other program in response 
to the other program not being on the safe list. 

32. (Original) The method of claim 30, further comprising forming a log to record any 
predetermined file system operations. 

33. (Original) The method of claim 30, further comprising providing means to flag the 
other program in response to at least one of: 

the other program opening a local file on a local file system to perform a read 
operation and opening a shared file on a shared or network file system to perform a write or append 
operation with the local file; 
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the other program reading or opening itself and the other program attempting to write 
or append itself or any content to the shared file on the shared or network file system or to write or 
append itself or any content to the local file on the local file system; 

the other program attempting to write or append the local file to the shared or 
network file system and preserve a filename of the local file in the shared or network file system; 
and 

the other program attempting to write or append a remote file to the local file system. 

34. (Original) The method of claim 30, further comprising providing means to flag the 
other program in response to the other program attempting to perform one of the predetermined file 
system operations. 

■i 

35. (Original) The method of claim 34, further comprising providing means to send an 
alert in response to flagging the other program. 

36. (Original) The method of claim 34, further comprising: 
providing a network monitoring system; and 

providing means to send an alert to the network monitoring system in response to 
flagging the other program. 

37. (Original) The method of claim 34, further comprising: 
providing means to present an alert to a user; and 

providing means for the user to approve the one of the predetermined file system 
operations before being performed by the other program. 

38. (Previously Amended) A computer-readable medium having computer-executable 
instructions for performing a method, comprising: 
allowing a security level to be set; 

monitoring predetermined file system operations associated with a program; and 
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logging any predetermined file system operations associated with the program 
including recording a filename and a location where a file is written without performing any virus 
scanning and detection actions . 

39. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising selecting the program for monitoring in 
response to the program not being on a safe list. 

40. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising following a predefined procedure in 
response to a level of security set. 

41. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising flagging the program in response to the 
program attempting to perform one of the predetermined file system operations. 

42. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 41, further comprising flagging the program in response to at least 
one of: 

the program opening a local file on a local file system to perform a read operation 
and opening a shared file on a shared or network file system to perform a write or append operation 
with the local file; 

the program reading or opening itself and the program attempting to write or append 
itself or any content to the shared file on the shared or network file system or to write or append 
itself or any content to the local file on the local file system; 

the program attempting to write or append the local file to the shared or network file 
system and preserve a filename of the local file in the shared or network file system; and 

the program attempting to write or append a remote file to the local file system. 
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43. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 41, further comprising inhibiting any predetermined file system 
operations associated with the program in response to the program being flagged. 

44. (Original) The computer-readable medium having computer executable instructions for 
performing the method of claim 38, further comprising sending an alert in response to the program 
attempting to perform any predetermined file system operations. 
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